Back to Database
Status published
High
CVE-2012-6426
LemonLDAP::NG before 1.2.3 does not use the signature-verification capability of...
Vulnerability Description
LemonLDAP::NG before 1.2.3 does not use the signature-verification capability of the Lasso library, which allows remote attackers to bypass intended access-control restrictions via crafted SAML data.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2012-6426
Credits & Attribution
No credits recorded in the NVD database.
References
More from lemonldap-ng
View All →CVE-2025-59518
In LemonLDAP::NG before 2.16.7 and 2.17 through 2.21 before 2.21.3,...
High
8
CVE-2025-31510
In the portal in LemonLDAP::NG before 2.21.0, cross-site scripting (XSS)...
High
7.2
CVE-2022-37186
In LemonLDAP::NG before 2.0.15. some sessions are not deleted when...
Unknown
0
CVE-2021-40874
An issue was discovered in LemonLDAP::NG (aka lemonldap-ng) 2.0.13. When...
Critical
9.8
CVE-2021-35472
An issue was discovered in LemonLDAP::NG before 2.0.12. Session cache...
High
8.8
Affected Vendor
lemonldap-ng
View all reports →Affected Software
lemonldap\
Vulnerable Versions:
\, 0
Timeline
Official Publish:
January 1st, 2013
Last Modified:
September 16th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.